Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

121 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Intel Quartus Prime9/2/202217/6/2026
Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access.
ModificadaAlta (7.8)0.22%—Intel Quartus Prime9/2/202217/6/2026
Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.22%—Intel Quartus Prime9/2/202217/6/2026
Improper permissions in the SafeNet Sentinel driver for Intel(R) Quartus(R) Prime Standard Edition before version 21.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.26%—Intel Quartus Prime9/2/202217/6/2026
Improper access control in a third-party component of Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.26%—Intel Quartus Prime9/2/202217/6/2026
Improper input validation in a third-party component for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.4)0.73%—Student Quarterly Grading System Project Student Quarterly Grading System24/1/202217/6/2026
Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute arbitrary code via the fullname and username parameters to the users page.
ModificadaAlta (7.8)0.29%—Intel Quartus17/2/202117/6/2026
Insecure inherited permissions for the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)1.2%—Intel Quartus Prime12/11/202017/6/2026
Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(R) Prime Standard Edition before version 20.2 may allow unauthenticated user to potentially enable information disclosure via network access.
ModificadaMedia (5.5)0.27%—Intel Quartus Prime12/11/202017/6/2026
Uncaught exception in the Intel(R) 50GbE IP Core for Intel(R) Quartus Prime before version 20.2 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (6.8)0.37%—Intel Quartus PrimeIntel Stratix 10 Fpga Firmware12/11/202017/6/2026
Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.1 may allow an unauthenticated user to potentially enable escalation of privilege and/or information disclosure via physical access.
ModificadaMedia (6.8)0.36%—Intel Quartus Prime PROIntel Stratix 10 Fpga Firmware12/11/202017/6/2026
Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.2 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
ModificadaMedia (5.5)0.30%—Intel Quartus Prime16/12/201917/6/2026
Null pointer dereference in the FPGA kernel driver for Intel(R) Quartus(R) Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.27%—Intel Quartus Prime16/12/201917/6/2026
Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)16%—Softwareag QuartzOracle Apache Batik MapviewerOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+2726/7/201917/6/2026
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
ModificadaAlta (7.8)0.32%—Intel Quartus IIIntel Quartus Prime17/5/201917/6/2026
Improper directory permissions in the installer for Intel(R) Quartus(R) software may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.35%—Intel Quartus Prime Programmer AND Tools10/7/201817/6/2026
Unquoted service paths in Intel Quartus Prime Programmer and Tools in versions 15.1 - 18.0 allow a local attacker to potentially execute arbitrary code.
ModificadaAlta (7.8)0.35%—Intel Quartus II Programmer AND Tools10/7/201817/6/2026
Unquoted service paths in Intel Quartus II Programmer and Tools in versions 11.0 - 15.0 allow a local attacker to potentially execute arbitrary code.
ModificadaAlta (7.8)0.35%—Intel Quartus II10/7/201817/6/2026
Unquoted service paths in Intel Quartus II in versions 11.0 - 15.0 allow a local attacker to potentially execute arbitrary code.
ModificadaAlta (7.8)0.35%—Intel Quartus Prime10/7/201817/6/2026
Unquoted service paths in Intel Quartus Prime in versions 15.1 - 18.0 allow a local attacker to potentially execute arbitrary code.
ModificadaMedia (6)1.9%—Quartz Plugin Project Quartz Plugin6/8/201417/6/2026
SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor privileges to execute arbitrary SQL commands via the quote parameter in an edit action in the quartz/quote_form.php page to wp-admin/edit.php.
ModificadaMedia (6.8)3.2%—Apple Quartz Composer3/8/200716/6/2026
Quartz Composer on Apple Mac OS X 10.4.10 does not initialize a certain object pointer, which might allow user-assisted remote attackers to execute arbitrary code via a crafted Quartz Composer file.